|
||||
Anti SQL Injection Code / Intro
Sql injection biasa berlaku kat login form. Katakan query anda seperti ini:
sql_send("insert into yajiv (name) value ('$name');"); Biasanya SQL Injection attack dilakukan pada Login form: User akan memasukkan username'nya (dalam field username) sebagai contoh di bawah Yajiv')"; delete * from names; Oleh Itu, SQL akan query berikut: insert into names (name) value ('Yajiv')"; delete * from names;'); Sekarang query default telah berubah kepada query baru. Sekiranya database tak secure, semua data dalam table names akan hilang Untuk mengelakkan kejadian di atas berlaku function berikut boleh membantu: <?PHP function stripQuotes($strWords) { $strWords = str_replace("''", "'", $strWords) return $strWords ; } function killChars($strWords) { $badChars = array("select", "drop", ";", "--", "insert", "delete", "xp_") ; str_replace() ; foreach($badChars as $current) { $strWords = str_replace($current, '', $strWords); } return $strWords ; } ?> Masukkan Code berikut dibahagian login process: $login = stripQuotes( $_POST['user'], $_POST['pass'] Oleh itu, function ini akan menapis ayat-ayat berikut: select drop" ; -- insert delete xp_ (Anda boleh edit sendiri) Sekarang site dah selamat daripada SQL Injection. Untuk keterangan lanjut sila layari: http://www.sqlsecurity.com/ Selamat Mencuba ![]() Last edited by YajivMalhotra; 11-10-2004 at 01:01 AM. |
|
||||
oit YajivMalhotra, buh sekali la... XSS vuln ngan remote shell execution thru PHP code.... depa nak tau gak tue....
![]()
__________________
<form name="jump"> <select name="menu" onChange="location=document.jump.menu.options[document.jump.menu.selectedIndex].value;" style="border:1px #393F31 solid;color:#393F31;font:10px Verdana;font-weight:bold;" > <option value="0" style="background: #9CC8FE" selected>*SELECT-LINKS</option> <option value="http://www.gengturbo.org/" style="background: #FF0000">GENGTURBO</option> <option value="http://www.phixelgrafix.com/" target="new" style="background: #C6D607">PHIXELGRAFIX</option> <option value="http://dailydigital.phixelgrafix.com/" style="background: #FCBC45">OLD-BLOG</option> <option value="http://www.mesrahosting.net/" style="background: #FF99CC">WEBHOSTING</option> </select> </form> |
|
|||
|
|
![]() |
«
Previous Thread
|
Next Thread
»
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Anti-Spam Software | Terry | Paid Hosting Discussion Forum | 3 | 28-11-2006 11:50 AM |
| setup anti spam use oss | linasham | Mamak Stall | 1 | 22-09-2006 01:55 PM |
| About XSS Injection | YajivMalhotra | Website Programming | 3 | 11-10-2004 03:53 PM |
| sql injection | MHR | Website Programming | 7 | 08-10-2004 03:03 PM |
| the best anti virus! | fadlee | Mamak Stall | 30 | 08-10-2004 09:00 AM |
All times are GMT +8. The time now is 12:02 PM.
Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0 vBulletin skin by ForumMonkeys.com.
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0 vBulletin skin by ForumMonkeys.com.












.... aku lemah lah dalam hal hacker/cracker ni semua.. 
Linear Mode

